CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLittlecms+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Sep 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second...Show more |
6Canonical DebianLittlecms+3 more19Active Iq Unified Manager Debian LinuxE Series Santricity Management+16 moreMay 13, 2026 Feb 3, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more |
1Littlecms 1Little Cms Color Engine May 6, 2026 May 7, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in t...Show more |
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4...Show more |
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIF...Show more |
1Littlecms 2Lcms Little Cms Color EngineApr 23, 2026 Dec 3, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" va...Show more |
1Littlecms 2Lcms Little Cms Color EngineApr 23, 2026 Dec 3, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency inv...Show more |